MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0ced8608b564d9119787e2cc90c185429eb9326a41f3c51b3b22fc8810d43c32. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ConnectBack


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments 1

SHA256 hash: 0ced8608b564d9119787e2cc90c185429eb9326a41f3c51b3b22fc8810d43c32
SHA3-384 hash: 7296accc757b8bcb90a2398887070a47fdc24fc2f081965d69c3eec4283eb7bdfaca6c9b0924baa47baae7b6cf25e870
SHA1 hash: 5e90b9c7b6c4f67d4fb96e44eb78c592b66de2e2
MD5 hash: 0bc69734deea542ed7246a4a57189bfb
humanhash: lamp-oscar-beer-oregon
File name:0bc69734deea542ed7246a4a57189bfb
Download: download sample
Signature ConnectBack
File size:250 bytes
First seen:2024-07-04 06:38:03 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 3:Bnks//xlEldl1llXllS/rltll3llvlfXwvlltPNTSiPHZYC1E3w/FQqoRQC+ys5t:BnX//In8/r1GBxH2TOQ3RQdygg5XJYD
TLSH T198D080330B4AC0DFDAD4563F56745DBCE77F9675474867710810DC011C1A6446F62C75
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Reporter zbetcheckin
Tags:64 ConnectBack elf

Intelligence


File Origin
# of uploads :
1
# of downloads :
117
Origin country :
FR FR
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Connection attempt
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
UPX
Botnet:
unknown
Number of open files:
0
Number of processes launched:
1
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
no suspicious findings
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Result
Verdict:
MALICIOUS
Malware family:
Metasploit Framework
Verdict:
Malicious
Result
Threat name:
ConnectBack
Detection:
malicious
Classification:
troj
Score:
76 / 100
Signature
Antivirus / Scanner detection for submitted sample
Found malware configuration
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Yara detected ConnectBack
Behaviour
Behavior Graph:
Threat name:
Linux.Backdoor.ConnectBack
Status:
Malicious
First seen:
2024-07-03 18:48:07 UTC
File Type:
ELF64 Little (Exe)
AV detection:
17 of 24 (70.83%)
Threat level:
  5/5
Result
Malware family:
connectback
Score:
  10/10
Tags:
family:connectback linux
Malware Config
C2 Extraction:
89.197.154.116:7810
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ConnectBack

elf 0ced8608b564d9119787e2cc90c185429eb9326a41f3c51b3b22fc8810d43c32

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh

Comments



Avatar
zbet commented on 2024-07-04 06:38:04 UTC

url : hxxp://89.197.154.116/LauncherR.elf